Security Audit

Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.

Trainings

We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.

 

OS X Yosemite

Apple's OS X Yosemite has been found with a serious vulnerability allowing an attacker to take control of your computer, as told by a Swedish white-hat hacker.

Emil Kvarnhammar, Swedish Security firm Truesec's hacker, named the vulnerability as "rootpipe" and explained how he got this security hole in reputed Apple's OS X (10.10) Yosemite.

The vulnerability is so serious that even without the authorization, an attacker could gain the highest level of access on the machine called root access.That leads to complete control of the system.

Truesec declines to provide the details as Apple hasn't fixed the flaw yet but they are awaiting a patch to roll out soon and then they will release the full report.

This is what the White-hat hacker,Emil said:

It all started when I was preparing for two security events, one in Stockholm and one in Malm. I wanted to show a flaw in Mac OS X, but relatively few have been published. There are a few proof of concepts online, but the latest I found affected the older 10.8.5 version of OS X. I couldn't find anything similar for 10.9 or 10.10.

Then he experimented with version 10.8.5 of the OS and got it work,he says.But hard luck on version 10.9.

I was a bit dejected but continued to investigate,There were a few small differences [in later releases] but the architecture was the same. With a few modifications I was able to use the vulnerability in the latest Mac OS X, version 10.10. , Emil added.

He shared his experiences while trying to find vulnerability.He told that he thinks like a developer while finding vulnerabilities in an OS.In this case,Apple had relocated some functions, but the basic flaws were intact.

Further he explained, that Normally there are sudo password requirements, which work as a barrier, so the admin can't gain root access without entering the correct password. However, rootpipe circumvents this,

The very next day of the discovery, Emil reported the vulnerability to Apple.

Due to Apple's policy of not confirming the vulnerabilities, didn't surprised him with very less response on the report.But when he asked for the date for publishing the flaw, apple indirectly confirmed it.

At last he said, For our part, there was no discussion: we do responsible disclosure,But we also wanted to announce that we found a serious flaw; there is a big risk here. In our dialogue with Apple, we agreed on a date for full disclosure. After this date, we can talk about exactly what we found", he ended with this.

But before ending we tried to ask how he named the vulnerability as "rootpipe", but he denied telling the story as it would reveal the vulnerability to much, which can't be done before the report is to be published.

The complete vulnerability report is likely to be published in January.

Taking in account, Apple takes security and flaws very seriously and even sometimes act carefully about the information they disclose, because of their reputation and image they have maintained for their softwares tending to be as safe as possible.But after all, its very common to think OS X is critically vulnerable. There are surely number of flaws.

Advisory:

Emil suggested the protection can be done before Apple roll out the fix, that make sure you avoid using admin account on daily basis.But since most Macs set up with only single account on them, and that has root access,so its a bit of tricky.He suggested that you can make a new account and assign it admin rights, and call that "admin" or something similar. Then simply log in to this new account and remove permissions from the default admin account that you might be using daily.

This prevents hackers from taking control of the full system, in case they hack the system, and hence can make least harm to the system.Though the users have to put password over and again whenever they have to install some new software or so, but its worth the headache till the fix rolls out for the vulnerability.

Last words from Emil were, This is a great way of protecting your data, especially if your computer gets stolen,

See more of Cyber Intelligence by logging in.
Connect with cyber security experts,Discover job opportunities,Online Training, Information Security Advisory and lot more.